| PROBLEM: | There are numerous vulnerabilities in Internet Explorer: 1) Cascading Style Sheets (CSS) heap memory corruption; 2) Similar method name redirection cross domain vulnerability; 3) Install engine vulnerability; 4) Drag and drop vulnerability; 5) Address bar spoofing on double byte character set locale vulnerability; 6) Plug-in Navigation address bar spoofing vulnerability; 7) script in Image Tag file download vulnerability; 8) SSL caching vulnerability. |
| PLATFORM: | Affected Software: • Microsoft Windows NT Server 4.0 Service Pack 6a • Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 • Microsoft Windows 2000 Service Pack 3 and Microsoft Windows 2000 Service Pack 4 • Microsoft Windows XP, Microsoft Windows XP Service Pack 1, and Microsoft Windows XP Service Pack 2 • Microsoft Windows XP 64-Bit Edition Service Pack 1 • Microsoft Windows XP 64-Bit Edition Version 2003 • Microsoft Windows Server 2003 • Microsoft Windows Server 2003 64-Bit Edition • Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (Me) – Review the FAQ section of this bulletin for details about these operating systems. Affected Components: • Internet Explorer 5.01 Service Pack 3 on Windows 2000 SP3: Download the update. • Internet Explorer 5.01 Service Pack 4 on Windows 2000 SP4: Download the update. • Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Me: Download the update. • Internet Explorer 6 on Windows XP: Download the update. • Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 3, on Microsoft Windows 2000 Service Pack 4, on Microsoft Windows XP, or on Microsoft Windows XP Service Pack 1: Download the update. • Internet Explorer 6 Service Pack 1 on Microsoft Windows NT Server 4.0 Service Pack 6a, on Microsoft Windows NT Server 4.0 Terminal Service Edition Service Pack 6, on Microsoft Windows 98, on Microsoft Windows 98 SE, or on Microsoft Windows Me: Download the update. • Internet Explorer 6 for Windows XP Service Pack 1 (64-Bit Edition): Download the update. • Internet Explorer 6 for Windows Server 2003: Download the update. • Internet Explorer 6 for Windows Server 2003 64-Bit Edition and Windows XP 64-Bit Edition Version 2003: Download the update. • Internet Explorer 6 for Windows XP Service Pack 2: Download the update. |
| DAMAGE: | An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full provileges. |
| SOLUTION: | Install the update immediately. |
| VULNERABILITY ASSESSMENT: |
The risk is HIGH. An attacker could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. The user would have to be coerced to visit a malicious website. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/p-006.shtml |
| ORIGINAL BULLETIN: | http://www.microsoft.com/technet/security/bulletin/ms04-038.mspx |
| CVE/CAN: | http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CAN-2004-0842 CAN-2004-0727 CAN-2004-0216 CAN-2004-0839 CAN-2004-0844 CAN-2004-0843 CAN-2004-0841 CAN-2004-0845 |
[***** Start Microsoft Security Bulletin MS04-038 *****] Microsoft Security Bulletin MS04-038 Cumulative Security Update for Internet Explorer (834707) Issued: October 12, 2004 Version: 1.0 Summary Who should read this document: Customers who use Microsoft Windows Impact of Vulnerability: Remote Code Execution Maximum Severity Rating: Critical Recommendation: Customers should install the update immediately. Security Update Replacement: This update replaces the update that is included with Microsoft Security Bulletin MS04-025. That update is also a cumulative update. Caveats: Microsoft Knowledge Base Article 834707 documents the currently known issues that customers may experience when they install this security update. The article also documents recommended solutions for these issues. This update may not include hotfixes that have been released since the release of MS04-004 or MS04-025. Customers who have received hotfixes from Microsoft or from their support providers since the release of MS04-004 or MS04-025 should review the FAQ section for this update to determine how this update might affect their operating systems. This update contains several functionality and security changes which are documented in the FAQ section for this update.
Tested Software and Security Update Download Locations:
Affected Software:
| • | Microsoft Windows NT Server 4.0 Service Pack 6a |
| • | Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 |
| • | Microsoft Windows 2000 Service Pack 3 and Microsoft Windows 2000 Service Pack 4 |
| • | Microsoft Windows XP, Microsoft Windows XP Service Pack 1, and Microsoft Windows XP Service Pack 2 |
| • | Microsoft Windows XP 64-Bit Edition Service Pack 1 |
| • | Microsoft Windows XP 64-Bit Edition Version 2003 |
| • | Microsoft Windows Server 2003 |
| • | Microsoft Windows Server 2003 64-Bit Edition |
| • | Microsoft Windows 98, Microsoft Windows 98 Second Edition (SE), and Microsoft Windows Millennium Edition (Me) – Review the FAQ section of this bulletin for details about these operating systems. |
Affected Components:
| • | Internet Explorer 5.01 Service Pack 3 on Windows 2000 SP3: Download the update. |
| • | Internet Explorer 5.01 Service Pack 4 on Windows 2000 SP4: Download the update. |
| • | Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Me: Download the update. |
| • | Internet Explorer 6 on Windows XP: Download the update. |
| • | Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 3, on Microsoft Windows 2000 Service Pack 4, on Microsoft Windows XP, or on Microsoft Windows XP Service Pack 1: Download the update. |
| • | Internet Explorer 6 Service Pack 1 on Microsoft Windows NT Server 4.0 Service Pack 6a, on Microsoft Windows NT Server 4.0 Terminal Service Edition Service Pack 6, on Microsoft Windows 98, on Microsoft Windows 98 SE, or on Microsoft Windows Me: Download the update. |
| • | Internet Explorer 6 for Windows XP Service Pack 1 (64-Bit Edition): Download the update. |
| • | Internet Explorer 6 for Windows Server 2003: Download the update. |
| • | Internet Explorer 6 for Windows Server 2003 64-Bit Edition and Windows XP 64-Bit Edition Version 2003: Download the update. |
| • | Internet Explorer 6 for Windows XP Service Pack 2: Download the update. |
The software in this list has been tested to determine if the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support lifecycle for your product and version, visit the Microsoft Support Lifecycle Web site.